CompanySep 11, 2026

CCTV Design Tool is now part of TechMagic: what changes for you, and what does not

person

CCTV Design Tool Team

Editorial Team

CCTV Design Tool is now part of TechMagic: what changes for you, and what does not

In August 2026, CCTV Design Tool was acquired by TechMagic, an international software engineering group. Since then, some of our customers, and at least one competitor, have raised reasonable points: who holds your data now, where it lives, and what you should update in your own GDPR records as a result.

Those are exactly the right things to check with any vendor after an acquisition, so this post covers all of them directly, in writing, with documents you can attach to your compliance file. If you need more than what is here, email us and we will complete your security questionnaire or send you a signed DPA.

The short version

  • Your contracting entity and data processor is TECHMAGIC UK LTD, a United Kingdom company. The UK is covered by the European Commission's adequacy decision.
  • Your project data is stored only in the EU (AWS eu-central-1 and eu-north-1). Nothing moved because of the acquisition.
  • TechMagic's management systems are certified to ISO/IEC 27001:2022 and ISO 9001:2015, independently audited, with certificates you can verify.
  • Zero-Knowledge encryption and local-only storage still exist, and your organisation admin can enforce them, which means you can configure the product so that we are technically unable to read your projects, or never receive them at all.
  • You can export or permanently delete your data at any time. We do not sell your data, and we do not use your project content to train AI models.

What actually happened

TechMagic acquired CCTV Design Tool in August 2026. The product keeps its own brand, roadmap and dedicated delivery team; TechMagic provides corporate, legal and compliance functions, plus additional engineering, design and AI expertise. For customers, the practical outcome of the acquisition is more investment in the product, not a change in how your data is handled.

An acquisition is not a data breach and does not change your legal protections, but it does mean your records should reference the correct legal entity. Everything you need for that update is below.

The legal entity behind the tool

The contracting entity is TECHMAGIC UK LTD, registered at 41 Devonshire Street, Ground Floor, London W1G 7AJ, United Kingdom, VAT number GB 409 6531 89. This is the entity that operates the service and that your processing agreement runs with. The TechMagic group also includes entities in Poland (TechMagic PL Sp. z o.o.), Ukraine (TechMagic LLC) and the United States (Dynamo Development Inc.); we list them openly because transparency beats guesswork, and because access by group personnel is governed by the safeguards described below.

If you maintain an Article 30 record of processing activities, update the processor name to TECHMAGIC UK LTD. That is the entirety of the paperwork change on your side.

Where your data lives, and who can reach it

Storage location and access location are two different things, and we are explicit about both.

Storage: the service runs entirely on EU-based cloud infrastructure, Amazon Web Services regions eu-central-1 and eu-north-1. Floor plans, device data and project files are stored within the European Union and are not transferred outside the EEA for storage. Backups are encrypted and also stored in EU cloud storage.

Access: AWS infrastructure access is restricted to named engineers and protected with multi-factor authentication. Where TechMagic personnel outside the EEA require access for support or engineering purposes, that access is governed by appropriate legal safeguards: the UK is covered by the European Commission's adequacy decision, and Standard Contractual Clauses apply elsewhere. We treat remote access as the transfer it legally is, and we paper it accordingly.

And if that is still not enough for your client's threat model, you can remove us from the equation entirely; see the storage policy section below.

Our sub-processors, current and on request

Our current sub-processors are: Amazon Web Services (hosting and storage, EU regions), Mailgun (transactional email, EU endpoint), Lemon Squeezy (payments, as Merchant of Record), Sentry (error monitoring, EU ingest with PII disabled), Google (OAuth sign-in and map imagery), and Mapbox / Esri ArcGIS (satellite and map imagery). A current list is available on request at any time, and we notify customers of material changes, consistent with Article 28(2). If you hold an older version attached to your contract, ask us and we will send the current one with a change log.

Transfer safeguards, in writing

For the UK leg, the European Commission adequacy decision. For any access by group personnel outside the EEA, Standard Contractual Clauses. A Data Processing Agreement is available to enterprise customers on request, and we are glad to complete your security questionnaire so the answers sit in your file rather than on our blog. Email contact@cctvdesigntool.com and you will receive documents, not reassurance.

Getting your projects out

You can request a full export or permanent deletion of your data at any time. Account deletion removes your data from the database; after a project is deleted, associated images are retained for up to 90 days solely for backup recovery, then permanently deleted, or immediately on explicit request. And if you use local-only mode, your projects are already files on your own machine, so portability is not something you have to request from us in the first place.

You choose how much we can see

This has been the core of our security model since long before the acquisition, and it is worth restating because it makes most transfer questions moot. There are three storage levels, and an organisation administrator can enforce one policy for the whole team:

  • Standard cloud storage. Projects encrypted in transit (TLS 1.2+) and at rest (AES-256), stored in the EU.
  • Cloud with Zero-Knowledge encryption. Projects are encrypted inside your browser with AES-256-GCM, using a key derived from your passphrase, before anything reaches us. Our servers only ever hold ciphertext. Our own administrators cannot read your project content, and neither could an attacker who breached our infrastructure, and neither could anyone who acquired the company.
  • Local-only. Projects never leave your device. There is no project data on our servers to expose, share, subpoena or transfer, in any direction, to any country.

Admins can additionally block server-side PDF export, so document generation also happens on the device. If your internal policy says client site plans must never sit in a third-party cloud, you can enforce exactly that and keep using the tool.

A camera plan shows where every camera points and, by implication, where the blind spots are. We agree that it deserves to be treated as security documentation, which is precisely why we built modes where we cannot read it or never receive it.

Independently certified, independently verifiable

TechMagic's management systems are certified to ISO/IEC 27001:2022 (Information Security Management, certificate no. 4159904) and ISO 9001:2015 (Quality Management, certificate no. 4159903), issued by Quay Audit UK Ltd on 19 September 2025 and valid until 19 September 2028. You do not have to take our word for it: validity can be confirmed against the International Register of Quality Assessed Organisations (www.irqao.com), and scanned copies are appended to our Information Security Overview, available on request.

What we will never do with your data

  • We do not sell your data, to brokers, advertisers or anyone else.
  • We do not use your project content to train AI models.
  • We do not share your designs or client project information with third parties for advertising.

Our revenue comes from subscriptions. That did not change with the acquisition, and there is no business model here that depends on monetising what you upload.

What we are still building

Honesty cuts both ways, so here is what is on the security roadmap rather than already shipped: organisation-wide enforced 2FA, detailed enterprise audit logs for administrative and data-access actions, a formalised documented incident-response plan aligned to the group ISMS, ISO/IEC 42001 certification planned for completion by the end of 2026, and evaluation of SOC 2 as we scale. When a vendor tells you everything is already perfect, be suspicious. We would rather tell you what is in progress.

What you should actually do now

  1. Update your Article 30 record to name TECHMAGIC UK LTD as the processor.
  2. Request the current DPA and sub-processor list from contact@cctvdesigntool.com if you want them in your file.
  3. If your clients include banks, government facilities or critical infrastructure, consider enforcing Zero-Knowledge or local-only mode at the organisation level. It takes an admin a minute.
  4. Keep the reply we send you. If a tender ever asks how you assured yourself about your design toolchain, that email thread is your answer.

Questions, questionnaires, DPA requests or vulnerability reports: contact@cctvdesigntool.com. We answer with documents attached.

TECHMAGIC UK LTD, 41 Devonshire Street, Ground Floor, London W1G 7AJ, United Kingdom. VAT GB 409 6531 89.

Besplatno probno razdoblje

Želite li isprobati sami?

Počnite dizajnirati profesionalne sigurnosne sustave već danas. Za prvi projekt nije potrebna kreditna kartica.